Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-40183

Enforce password complexity on the reset password page

    XMLWordPrintable

Details

    • 1
    • 2
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

    Description

      NOTE: This suggestion is for JIRA Server. Using JIRA Cloud? See the corresponding suggestion.

      Our users bristle at the thought of changing their JIRA password because of the unfriendly nature of the "Reset Password" page (ResetPassword!default.jspa)

      This request entails:

      1. can the reset page discover the password complexity rules
      2. have those rules be enforced on the page, graying out the "submit" button if a password does not meet those rules

      We get so many emails from frustrated users that this enhancement would certainly help alleviate the angst for our JIRA users.

      An example of a "happy" user:

      The ***** JIRA has literally the worst login & forgot your password flow I've ever encountered. I want to kill someone after using it, it's so shitty. Let me give you just the bare minimum set of features that are broken:
      1) No visibility into why already-working passwords have broken.
      2) The login link sent in a FYP email SAYS it works for 24 hours, but in reality works for exactly ONE try.
      3) The requirements for password strength are ridiculous for an internal tool. Especially when combined with bug #2.
      4) Even after resetting correctly, I can't fucking login. I can cut & paste the EXACT form entry, and it won't work. I can manually type it in, in case there's some ridiculous restriction on cut & pasting, and login credentials are still rejected.

      Please fix this festering pile of crap. If it weren't for the fact that useful data is only available in this bug tracker, I'd never use it again. Luckily for JIRA, it has a captive audience, so I can't leave with my wallet.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              be67fb543225 Bill Cowden
              Votes:
              8 Vote for this issue
              Watchers:
              11 Start watching this issue

              Dates

                Created:
                Updated: